Weaknesses of type CWE-754

461 results

Falta de tratamento de condições excepcionais

O código não valida ou valida incorretamente situações anormais que raramente ocorrem durante a operação normal do sistema. Isso deixa o software vulnerável quando essas condições inesperadas finalmente acontecem — erros silenciosos, comportamentos indefinidos ou falhas de segurança podem ser explorados ou danificar a aplicação.

Example

Um servidor web processa uploads e assume que a pasta temporária sempre terá espaço disponível, sem checar se o disco está cheio. Quando o espaço acaba, o código falha silenciosamente, deixando requisições pendentes ou corrompidas, ou causando denial of service.

How to mitigate

Implemente validações explícitas para cenários fora do caminho feliz: verificar retornos de erro de chamadas de sistema (create, malloc, fopen), definir timeouts, validar limites de recursos e registrar falhas excepcionais com logging adequado. Trate toda exceção esperada, mesmo que rara.

CVE-2021-22746Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems thatEPSS 0.2%CVE-2024-39519HIGHJunos OS Evolved: ACX 7000 Series: Multicast traffic is looped in a multihoming EVPN MPLS scenarioEPSS 0.2%CVE-2024-54115MEDIUMOut-of-bounds read vulnerability in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.EPSS 0.2%CVE-2021-22745Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems thatEPSS 0.2%CVE-2024-54116MEDIUMOut-of-bounds read vulnerability in the M3U8 module Impact: Successful exploitation of this vulnerability may cause features to perform abnoEPSS 0.2%CVE-2021-22747Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems thatEPSS 0.2%CVE-2026-73288MEDIUMRustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deletedEPSS 0.2%CVE-2022-47111LOW7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later versions are unaffectEPSS 0.2%CVE-2026-4054MEDIUMSVG content served through Mattermost image proxy despite Content-Type restrictions causes client-side denial of serviceEPSS 0.2%CVE-2026-34066MEDIUMnimiq-blockchain: Peer-triggerable panic during history syncEPSS 0.2%CVE-2023-44196MEDIUMJunos OS Evolved: PTX10003 Series: Packets which are not destined to the router can reach the REEPSS 0.2%CVE-2026-39395MEDIUMCosign's verify-blob-attestation reports false positive when payload parsing failsEPSS 0.2%CVE-2021-33147MEDIUMImproper conditions check in the Intel(R) IPP Crypto library before version 2021.2 may allow an authenticated user to potentially enable infEPSS 0.2%CVE-2025-8716MEDIUMCache exploitation vulnerabilityEPSS 0.2%CVE-2024-50195HIGHposix-clock: Fix missing timespec64 check in pc_clock_settime()EPSS 0.2%CVE-2021-29607MEDIUMIncomplete validation in `SparseSparseMinimum`EPSS 0.2%CVE-2025-0116MEDIUMPAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted LLDP FrameEPSS 0.2%CVE-2024-50184MEDIUMvirtio_pmem: Check device status before requesting flushEPSS 0.2%CVE-2021-22743Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex TCM 4351B installed on Tricon V11.3.x systems that couEPSS 0.2%CVE-2026-0269MEDIUMPAN-OS: Denial of Service (DoS) in Tunnel Traffic ProcessingEPSS 0.2%